Connect read-only
Use OAuth for GCP Cloud Audit Logs or a customer-created IAM role for recent regional AWS CloudTrail management events.
Cloud security without SIEM overhead
Flare turns cloud and SaaS audit activity into ranked, explained findings. GCP, AWS and Google Workspace are available today. GitHub Enterprise Cloud audit logs are coming soon.
How it works
Flare is designed for teams that need useful cloud-audit answers without operating a general-purpose log platform.
Security monitoring for small businesses Security vs cost anomaly detectionUse OAuth for GCP Cloud Audit Logs or a customer-created IAM role for recent regional AWS CloudTrail management events.
Flare assesses current-window evidence with available historical context, then ranks findings by severity with a plain-English explanation.
Inspect selected source-event excerpts and ask follow-up questions using the retained analysis results and supporting evidence.
Source coverage
Admin Activity, System Event, and Policy Denied logs, with Data Access available when it is enabled and separately authorized.
Explore GCP Audit Log anomaly detection →Review GCP access requirements →Recent regional CloudTrail management-event history through a read-only IAM role with a connector-specific ExternalId.
Explore AWS CloudTrail anomaly detection →Review AWS access requirements →Login, administrator and OAuth-token audit activities for one verified customer. Read-only access and manual analysis; no message or file content.
Explore Workspace coverage and setup →Planned support for organization web audit events with read-only access. Git operations and repository contents are excluded.
Learn about GitHub audit logs →Start with real evidence
Connect read-only or upload a focused JSON, NDJSON, CSV, or plain-text log file. Flare is free during the open beta.
Start free